Ransomware Negotiators Became Insider Force Multipliers

The real risk is not just ransomware operators on the outside. It is trusted negotiators inside incident response firms who can hand attackers the victim’s leverage points, turning a settlement process into a ransom-maximizing tool. Court documents say former DigitalMint employee Angelo Martino pleaded guilty after sharing victims’ negotiation positions and insurance policy limits with BlackCat operators. Two other negotiators, Ryan Clifford Goldberg and Kevin Tyler Martin, also pleaded guilty, and the victims included at least five U.S. organizations with ransom demands reaching $25.66 million and $26.793 million. The pattern matters because insurance limits and negotiation posture are exactly the details that shape payout pressure. That kind of insider access can raise criminal returns even when the malware itself does not change.

Part of the PlainSec briefing for 2026-04-22

Sources